Priority is set by the volume and the sensitivity of the data and by the type of data the supplier can reach, so start with the processors carrying the highest risk. In practice that puts the suppliers handling high volumes or special-category personal data first: cloud infrastructure, CRM, payroll and HR, the call centre, and marketing analytics.
The update has to satisfy the requirements of the Personal Data Protection Law (No. 6698) for a written contract with the processor and for adequate technical and organisational measures and, where data is shared with the EU, the General Data Protection Regulation and the rules on transfers abroad. The sub-processor chain, the retention periods, the breach notification deadlines and the audit rights deserve particular attention. The right method is a risk-ranked renewal plan built on the data inventory, so that limited resources go to the contracts that matter most.
Shall we apply this matter to your situation?
Tell us your specific situation in a few sentences; we'll assess it with the right team.